🇺🇸
TPI-Abuse
2026-09-13 02:17:23
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 22:17:16.832410 2026] [security2:error] [pid 11682:tid 11682] [client 34.62.90.52:53386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.williamrosscreations.com"] [uri "/.env.example"] [unique_id "aqYHrH794LZBnlxSpj4P1wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-12 07:41:20
(19 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 07:31:59
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:31:56.487412 2026] [security2:error] [pid 23938:tid 23950] [client 34.62.90.52:53930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.willowlanebooks.com|F|2"] [data ".willowlanebooks.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.willowlanebooks.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.willowlanebooks.com"] [unique_id "aqT_7PaghcYNgwj00eiiMgAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
palzer.IT
2026-09-11 18:20:30
(1 day ago)
Fail2ban automatic report for plesk-apache-badbot: 34.62.90.52 - - [11/Sep/2026:20:20:13 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 34.62.90.52 - - [11/Sep/2026:20:20:13 +0200] GET /settings%2F.env [DOMAIN_REMOVED] 404 6322 - Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +[DOMAIN_REMOVED]
show less
Bad Web Bot
🇳🇴
jad-abuse
2026-09-11 18:19:37
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: aws_creds ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: aws_creds, env_probe, git_exposure, source_backup, actuator, ssh_keys, credential_file, dotfile_probe. Observed by 1 sensor(s); 422 hits.
show less
Hacking
Web App Attack
🇮🇹
VHosting
2026-09-11 18:05:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:00:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:00:38.725893 2026] [security2:error] [pid 15735:tid 15817] [client 34.62.90.52:48046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wintechltd.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqRBxgsWsyxZW08dWAjpNQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
legionMCCXV
2026-09-11 17:59:30
(1 day ago)
Non-HTTP protocol data (e.g. MQTT/TLS handshake bytes) sent to HTTP(S) port.
Port Scan
Hacking
🇳🇱
Savvii
2026-09-11 17:21:16
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:04:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:04:02.531458 2026] [security2:error] [pid 31508:tid 31508] [client 34.62.90.52:36902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "windisfun.com"] [uri "/.env.local"] [unique_id "aqQ0glbCjPXZ0rhIF1lWTAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:27:09
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:27:00.890230 2026] [security2:error] [pid 15439:tid 15439] [client 34.62.90.52:57158] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||willowriver3.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "willowriver3.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqQr1PkaKt6FkJX0iKHTgQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 16:20:06
(1 day ago)
OS File Access Attempt. Matched phrase "proc/self" at ARGS:0. (930120-195)
Hacking
🇺🇸
TPI-Abuse
2026-09-11 16:11:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:11:23.550507 2026] [security2:error] [pid 12142:tid 12142] [client 34.62.90.52:39170] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williambarfoot.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williambarfoot.com"] [uri "/z9x8c7v6b5-debug-trigger-williambarfoot.com"] [unique_id "aqQoK0Yd0gvj-yVQafetlgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-11 15:59:23
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 15:55:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.90.52 (52.90.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:55:22.923849 2026] [security2:error] [pid 28842:tid 28842] [client 34.62.90.52:53452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildpete.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "aqQkasH-F7LDiaVbePer7gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack